🚨SlowMist TI Alert🚨 💸 @Bonfiretoken Loss: ~ $50k 🔍 Root Cause: Access control missing in BonfireSwap router's `transfer`. The function does not check `msg.sender == from` nor verify the caller's allowance on `from`, letting anyone set a victim as `from` and themselves as
BonfireSwap experienced a loss of approximately $50k due to a missing access control in its router's transfer function. The vulnerability allowed unauthorized users to transfer tokens by not verifying the caller's allowance.